PT-2022-12181 · Wondershare · Wondershare Dr.Fone
Published
2022-04-29
·
Updated
2022-09-09
·
CVE-2021-44595
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Wondershare Dr. Fone version as of 2021-12-06
Description
The issue allows a normal user to send manually crafted packets to the ElevationService.exe, enabling the execution of arbitrary code without validation and granting SYSTEM privileges.
Recommendations
For Wondershare Dr. Fone version as of 2021-12-06, consider restricting access to the ElevationService.exe until a patch is available to prevent exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wondershare Dr.Fone